Record summary

CVE-2021-31862 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Repository PoCs

GitHubRobertDra/CVE-2021-31862Repository PoCby RobertDraStars: 3Not analyzed1 file

755 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMSysAid 20.4.74 - Cross-Site ScriptingCVSS 6.1

SysAid 20.4.74 contains a reflected cross-site scripting vulnerability via the KeepAlive.jsp stamp parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade to a patched version of SysAid or apply the vendor-provided security patch to mitigate the XSS vulnerability.

WeaknessesCWE-79
Authorsjas37
Template tagscve2021cvexsssysaidvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:sysaid:sysaid:20.4.74:*:*:*:*:*:*:*
Shodan: http.favicon.hash:1540720428
FOFA: icon_hash=1540720428

Source: ProjectDiscovery

References

3